Data processing method and device, readable medium and electronic equipment

By determining and encrypting the target data unit after the video data encoding process, and adding an encryption identification unit to the video file, the problem of low encryption efficiency of video data in the prior art is solved, and partial encryption and efficient transmission of video data are realized.

CN120201212APending Publication Date: 2025-06-24BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311792443.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

When the prior art encrypts video data, the overall encryption efficiency is low, and it is difficult to realize partial encryption of video data, affecting transmission security and efficiency.

Method used

After the video data encoding process, the target data unit that needs to be encrypted is determined, the target video file containing the encryption identification unit is generated, which specifically includes: determining the target data unit, performing encryption processing, generating the encrypted data unit, and adding key verification data to the video file as the encryption identifier.

Benefits of technology

Encryption by selecting target data units, partial encryption of video data is achieved, encryption efficiency is improved, and while ensuring transmission security, the file processing process is simplified.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201212A_ABST
    Figure CN120201212A_ABST
Patent Text Reader

Abstract

The invention relates to a data processing method and device, a readable medium and electronic equipment, and the method comprises the steps: determining a target data unit needing to be encrypted in a plurality of data units obtained after the coding processing of video data; performing encryption processing on the target data unit to obtain an encrypted data unit; a target video file corresponding to the video data is generated at least according to the encrypted data unit, the target video file comprises an encryption identification unit used for representing that the file is encrypted, and the encryption identification unit at least comprises secret key verification data. Therefore, partial encryption of the video data can be realized according to requirements, the encryption efficiency is improved while the transmission security of the video data is ensured, and the encryption identification unit is added into the target video file to identify the target video file as encrypted data, so that the encryption efficiency is improved. The file receiving end can quickly identify the encrypted file through the encryption identification unit, and the decryption efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and in particular, to a data processing method, apparatus, readable medium, and electronic device. Background Art

[0002] With the development of computer technologies and Internet technologies, audio and video are increasingly transmitted over the network. To ensure the security of data transmission, data media encryption technologies are usually used to encrypt and protect media resources such as videos and audios, so as to improve the transmission security of digital media resources. Summary of the Invention

[0003] This Summary of the Invention section is provided to introduce concepts in a brief form, which will be described in detail in the subsequent Detailed Description section. This Summary of the Invention section is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to be used to limit the scope of the claimed technical solution.

[0004] In a first aspect, the present disclosure provides a data processing method, the method comprising:

[0005] Determine a target data unit to be encrypted among a plurality of data units obtained after encoding video data;

[0006] Perform an encryption process on the target data unit to obtain an encrypted data unit;

[0007] Generate a target video file corresponding to the video data at least based on the encrypted data unit, where the target video file includes an encryption identification unit for indicating that the file has been encrypted, and the encryption identification unit at least includes key verification data.

[0008] In a second aspect, the present disclosure provides a data processing method, the method comprising:

[0009] Obtain a target video file;

[0010] In response to detecting an encryption identification unit for indicating that the file has been encrypted in the target video file, perform data verification using the encryption identification unit;

[0011] In the case where the data verification is successful, read a plurality of data units included in the target video file;

[0012] In response to determining an encrypted data unit among the plurality of data units, perform a decryption process on the encrypted data unit to obtain a target data unit corresponding to the encrypted data unit;

[0013] Obtain video data corresponding to the target video file through a decoding process based on the target data unit.

[0014] In a third aspect, the present disclosure provides a data processing apparatus, the apparatus comprising:

[0015] A first determination module, configured to determine a target data unit to be encrypted among a plurality of data units obtained after encoding video data;

[0016] A first encryption module, configured to perform an encryption process on the target data unit to obtain an encrypted data unit;

[0017] A generation module, configured to generate a target video file corresponding to the video data at least according to the encrypted data unit, where the target video file includes an encryption identification unit for indicating that the file has been encrypted, and the encryption identification unit at least includes key verification data.

[0018] In a fourth aspect, the present disclosure provides a data processing apparatus, the apparatus comprising:

[0019] An acquisition module, configured to acquire a target video file;

[0020] A verification module, configured to perform data verification by using the encryption identification unit in response to detecting that an encryption identification unit for indicating that the file has been encrypted exists in the target video file;

[0021] A reading module, configured to read a plurality of data units included in the target video file in case the data verification is successful;

[0022] A decryption module, configured to perform a decryption process on the encrypted data unit in response to determining an encrypted data unit among the plurality of data units to obtain a target data unit corresponding to the encrypted data unit;

[0023] A decoding module, configured to obtain video data corresponding to the target video file through a decoding process according to the target data unit.

[0024] In a fifth aspect, the present disclosure provides a computer-readable medium, on which a computer program is stored, and when the program is executed by a processing apparatus, the steps of the method described in the first aspect or the second aspect of the present disclosure are implemented.

[0025] In a sixth aspect, the present disclosure provides an electronic device, comprising:

[0026] A storage device, on which a computer program is stored;

[0027] A processing device, configured to execute the computer program in the storage device to implement the steps of the method described in the first aspect or the second aspect of the present disclosure.

[0028] Through the above technical solution, among the multiple data units obtained after encoding and processing video data, a target data unit to be encrypted is determined, the target data unit is encrypted to obtain an encrypted data unit, and at least based on the encrypted data unit, a target video file corresponding to the video data is generated. The target video file includes an encryption identification unit for indicating that the file has been encrypted, and the encryption identification unit at least includes key verification data. Thus, the encryption of video data can be achieved by selecting the target data unit for encryption, and partial encryption of video data can be realized according to requirements, which can improve the encryption efficiency while ensuring the security of video data transmission. Moreover, for the encrypted situation, an encryption identification unit will be added to the finally generated target video file to indicate that the target video file is encrypted data, which is convenient for the receiving end of the target video file to quickly identify the encrypted file through the encryption identification unit and is beneficial to improving the decryption efficiency.

[0029] Other features and advantages of the present disclosure will be described in detail in the following specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In combination with the accompanying drawings and with reference to the following specific implementation, the above and other features, advantages and aspects of the embodiments of the present disclosure will become more obvious. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the original components and elements are not necessarily drawn to scale. In the drawings:

[0031] Figure 1 is a flowchart of a data processing method provided according to an embodiment of the present disclosure;

[0032] Figure 2 is a flowchart of a data processing method provided according to another embodiment of the present disclosure;

[0033] Figure 3 is a block diagram of a data processing device provided according to an embodiment of the present disclosure;

[0034] Figure 4 is a block diagram of a data processing device provided according to another embodiment of the present disclosure;

[0035] Figure 5 shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0037] It should be understood that the various steps recited in the method embodiments of the present disclosure can be executed in a different order and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.

[0038] The term "including" and its variations used herein are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0039] It should be noted that the concepts such as "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.

[0040] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0041] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0042] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0043] For example, when receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the technical solutions of the present disclosure according to the prompt message.

[0044] As an optional but non-limiting implementation, in response to receiving an active request from a user, the way to send a prompt message to the user can be, for example, in the form of a pop-up window. The prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0045] It can be understood that the above notification and the process of obtaining user authorization are only illustrative and do not limit the implementation of the present disclosure. Other ways that meet relevant laws and regulations can also be applied to the implementation of the present disclosure.

[0046] At the same time, it can be understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related provisions.

[0047] Before introducing the solution of the present disclosure, the application scenario of the present disclosure will be explained first. The present disclosure can be applied to the scenario of video transmission, which usually involves a video sender and a receiver.

[0048] Video is encoded at the sender side, that is, the original video data is compressed and encoded, usually in an encoder (such as an H.264 encoder) before the encapsulation stage. The encoder will convert the original video data into a format that conforms to video encoding, for example, NALU (that is, NAL Unit, full name Network Abstraction Layer Unit, network abstraction layer unit). NALU is a data unit in video encoding and is the basic data unit output by the video encoder. The encoded video frames are written into the output stream. Among them, if there is an encryption requirement, the data unit needs to be sent to the encryption processing module for encryption first and then the encrypted data unit is written into the output stream. After the encryption process is completed, the encrypted data unit is encapsulated into a container format, such as MP4 (Moving Picture Experts Group 4, dynamic image experts group), AVI (Audio Video Interleaved, audio-video interleaved format), MKV (Matroska Video File, a new multimedia encapsulation format), etc., to form a video file to be transmitted. The sender can transmit the formed video file outward, for example, to the receiver.

[0049] The processing process at the receiver side is opposite to that at the sender side, that is, first the obtained video file is unpacked, and then the result of unpacking is decoded. It should be noted that if the received video file has an encrypted part, the encrypted data unit needs to be sent to the decryption processing module for decryption before decoding.

[0050] In the related art, when it is necessary to encrypt and decrypt a video, the conventional solution is to encrypt and decrypt the entire video, that is, to encrypt and decrypt the data of each frame of the video, resulting in poor encryption and decryption performance and low efficiency.

[0051] To solve this problem, the present disclosure provides a data processing method, apparatus, readable medium, and electronic device to improve the encryption and decryption efficiency.

[0052] Figure 1 It is a flowchart of a data processing method provided according to an embodiment of the present disclosure. Optionally, this method can be applied to the sending end of video data. As Figure 1 shown, the method provided by the present disclosure may include steps 11 to 13.

[0053] In step 11, among the multiple data units obtained after encoding the video data, determine the target data unit to be encrypted.

[0054] As described above, the encoding process of video data is actually to convert each frame of the video data into a data unit that conforms to the video encoding format. For example, a NALU unit, and a NALU unit can represent a complete video frame or a part of a video frame. After encoding the video data, multiple data units corresponding to the video frames in the video data can be obtained, and among these data units, the target data unit to be encrypted can be determined first.

[0055] Optionally, the target data unit can be all or part of the multiple data units. For the case where the target data unit is all of the data units, it is equivalent to encrypting the entire video content of the video data. For the case where the data unit is part of the data units, it is equivalent to encrypting part of the video data. In practical applications, it can be flexibly selected according to actual needs.

[0056] Optionally, the target data unit can be the data unit corresponding to the key frame of the video data. Since when decoding, other video frames except the key frame need to be restored based on the key frame, that is, as long as the key frame cannot be decrypted, other video frames naturally cannot be restored either. Therefore, using the key frame of the video data as the target video frame for encryption can not only ensure encryption security but also improve the encryption efficiency, thus eliminating the need to encrypt each video frame.

[0057] Exemplarily, the key frame of the video data can be an IDR (Instantaneous Decoder Refresh) frame. Thus, in one possible implementation, the target data unit can be the data unit corresponding to the IDR frame of the video data. In this way, determining the target data unit is actually determining the NALU unit corresponding to the IDR frame.

[0058] In step 12, the target data unit is encrypted to obtain an encrypted data unit.

[0059] After determining the target data unit, the target data unit can be encrypted to obtain an encrypted data unit, and the obtained encrypted data unit can be written into the output stream.

[0060] Optionally, the target data unit can include a Header and a Data part. The header of the target data unit can be used to store the meta-information of the target data unit, and the data part of the target data unit can be used to store the video content of the video frame corresponding to the target data unit. Taking the target data unit as NALU as an example, it includes NALU Header and NALUData, and NALU Data is usually RBSP (Raw Byte Sequence Payload). Therefore, the encryption process for the target data unit can include the processing of both the header and the data part.

[0061] In one possible implementation, step 12 can include the following steps:

[0062] By encrypting the data part of the target data unit, the data part of the encrypted data unit is obtained;

[0063] By writing an encryption identifier into the target reserved bit of the header of the target data unit, the header of the encrypted data unit is obtained.

[0064] Optionally, any available encryption method (e.g., symmetric encryption, asymmetric encryption, etc.) can be used to encrypt the data part of the target data unit to form the encrypted data part as the data part of the encrypted data unit.

[0065] Optionally, by writing an encryption identifier into the target reserved bit of the header of the target data unit, the encrypted header can be formed as the header of the encrypted data unit.

[0066] In the header of the data unit, multiple reserved flag bits, that is, reserved bits, are usually set for future data expansion. Among them, the target reserved bit can be selected from the reserved bits in the header of the target data unit according to actual needs, and the number of bits of the target reserved bit can be 1 or more than 1.

[0067] In the case of using only one encryption method, the encryption identifier can indicate whether encryption is performed. In the case of using multiple encryption methods, in addition to indicating whether encryption is performed, the encryption identifier can also indicate the encryption type.

[0068] Taking the target data unit as the NALU as an example, the reserved bits (bits 41 - 47) in the nal_unit_type of the NALU Header can be used to write the encryption identifier to indicate that the video frame corresponding to the current NALU is encrypted.

[0069] In step 13, at least based on the encrypted data unit, a target video file corresponding to the video data is generated.

[0070] Among them, the target video file includes an encryption identifier unit for indicating that the file is encrypted, and the encryption identifier unit at least includes key verification data.

[0071] As described above, the target data unit can be all or part of multiple data units obtained after encoding the video data. That is to say, all or part of the video frames in the video data can be encrypted according to actual needs. Thus, any available encryption method (for example, symmetric encryption, asymmetric encryption, etc.) can be used for encryption, and the obtained new data unit is written into the output stream. For data units that do not need to be encrypted, they can be directly written into the output stream. It should be noted that for the case where there are more than one target data unit, the data parts of each target data unit can use the same encryption method or different encryption methods, and the present disclosure does not limit this.

[0072] Based on this, in a possible implementation manner, if the target data unit is part of multiple data units, step 13 may include the following steps:

[0073] Determine the first data unit among the multiple data units except the target data unit;

[0074] Generate a target video file by writing the first data unit and the encrypted data unit into a file.

[0075] That is to say, in the case of partial encryption, for the target data unit that needs to be encrypted, it is encrypted to obtain the encrypted data unit. For the first data unit that does not need to be encrypted, no encryption processing is required. Thus, the encrypted data unit and the first data unit are written into a file to generate a target video file.

[0076] In this way, partial encryption of the video data can be achieved, which can ensure the security of the file while also ensuring the processing efficiency of the file.

[0077] The aforementioned writing of a file actually writes to a specified container format to form a corresponding video file. The container format can be, for example, MP4, AVI, MKV, etc. Writing to the container format means organizing and storing the encoded data (such as the data units obtained after encoding, the encrypted data units) and the relevant metadata according to the specifications of the container format to form a complete video file. Optionally, a video file usually consists of multiple boxes, each box having its own structure and specifications, and different types of video files correspond to different box structures.

[0078] Optionally, the encryption identification unit can be provided as a box. Based on this, on the basis of the original video file structure, an encryption identification unit capable of characterizing that the file has been encrypted is added. In this way, it is possible to quickly determine whether the video file has been encrypted according to the video file. For example, if the video file contains an encryption identification unit, it means that the video file has been encrypted. If the video file does not have an encryption identification unit, it means that the video file has not been encrypted. Thus, the determination efficiency of whether the video file is encrypted can be improved. Optionally, the encryption identification unit can be located at the end of the target video file.

[0079] Optionally, the encryption identification unit can include a data header (Header) and a data body (Body). The data header can be used to store the meta-information of the encryption identification unit. For example, it stores information such as the size and type of the encryption identification unit box. The data body can be used to store key verification data.

[0080] In a possible embodiment, the key verification data can be generated in the following manner:

[0081] Determine a first key;

[0082] Encrypt the specified key information using the first key to obtain the key verification data.

[0083] The above processes of generating the first key and encrypting using the first key can adopt any available encryption method, for example, symmetric encryption, asymmetric encryption. Exemplarily, the asymmetric encryption method can be used to obtain the key verification data as described above, which has higher security.

[0084] The target video file generated after adding the encryption identification unit can be sent to any recipient of the video.

[0085] In the overall process of the present disclosure solution, after video data is encoded, the stage of writing to the output stream begins. One or more video frames to be encrypted can be selected, that is, the target data units are determined. The target data units are input into the encryption processing module to encrypt the data part of the target data units through the encryption processing module and write an encryption identifier to its header. At the same time, data units that do not need to be encrypted do not need to be input into the encryption processing module. Furthermore, the encrypted data units obtained after encryption and the unencrypted first data units are written into a file in a container format, and an encryption identifier unit is added to the file. Finally, it is encapsulated into the target video file.

[0086] Through the above technical solution, among the multiple data units obtained after encoding and processing video data, the target data units to be encrypted are determined, and the target data units are encrypted to obtain encrypted data units. And at least based on the encrypted data units, a target video file corresponding to the video data is generated, wherein the target video file contains an encryption identifier unit for indicating that the file has been encrypted, and the encryption identifier unit at least includes key verification data. Thus, the encryption of video data can be achieved by selecting the target data units for encryption, and partial encryption of video data can be realized according to requirements, while ensuring the security of video data transmission and improving the encryption efficiency. And for the encrypted situation, an encryption identifier unit will be added to the finally generated target video file to indicate that the target video file is encrypted data, which is convenient for the receiving end of the target video file to quickly identify the encrypted file through the encryption identifier unit, which is beneficial to improving the decryption efficiency.

[0087] Figure 2 It is a flowchart of a data processing method provided according to another embodiment of the present disclosure. Optionally, this method can be applied to the receiving end of video data. As Figure 2 shown, the method provided by the present disclosure can include steps 21 to 25.

[0088] In step 21, the target video file is obtained.

[0089] In step 22, in response to detecting that there is an encryption identifier unit in the target video file for indicating that the file has been encrypted, data verification is performed using the encryption identifier unit.

[0090] After obtaining the target video file, it can first be detected whether there is an encryption identifier unit in the target video file. If the encryption identifier unit is detected, it means that the target video file is an encrypted video file and cannot be directly read, and decryption processing is required. Before actual decryption, it is also necessary to first perform data verification using the encryption identifier unit, and after passing the verification, subsequent decryption processing can be performed.

[0091] In a possible implementation, the encryption identification unit may at least include key verification data. Based on this, data verification can be performed according to the key verification data in the encryption identification unit.

[0092] In a possible implementation, in step 22, using the encryption identification unit to perform data verification may include the following steps:

[0093] Determine the second key;

[0094] Use the second key to encrypt the specified key information to obtain an encrypted string;

[0095] If the encrypted string matches the key verification data, determine that the data verification is successful.

[0096] If the sending end of the video data encrypts the video, then the receiving end with read permission should store the relevant information for data verification. This relevant information may include the second key or the specified key information. The first key mentioned above and the second key here are both generated through a specific encryption method adopted during the video file generation process and are both completed based on existing encryption technologies, which will not be described in detail here.

[0097] Using the second key to encrypt the specified key information can obtain an encrypted string, and then compare the obtained encrypted string with the key verification data in the encryption identification unit. If the two can match (for example, be the same), it means that the current second key can successfully decrypt the encryption identification unit and the data verification is successful.

[0098] In step 23, in the case of successful data verification, read the multiple data units included in the target video file.

[0099] In the case of successful data verification, it means that the receiving end has the permission to read the video and can start reading the video file. Optionally, the target video file can be unpacked, and then the multiple data units included in the target video file can be read out.

[0100] Among these data units, there may be encrypted data units or data units that are not encrypted. For encrypted data units, additional decryption processing is required. Therefore, for each data unit, it is necessary to determine whether the data unit is an encrypted data unit.

[0101] As mentioned above, the data unit includes a header. Correspondingly, the encrypted data unit can be determined in the following way:

[0102] For each data unit, determine whether there is an encryption identification in the header of the data unit;

[0103] Determine the data unit with an encryption identifier as an encrypted data unit.

[0104] Combined with the previous description, the encryption identifier is added to the target reserved bit in the header of the data unit. Therefore, by identifying whether there is an encryption identifier in the header of the data unit, it is possible to quickly and accurately determine whether the data unit is an encrypted data unit.

[0105] If the header of the currently identified data unit contains an encryption identifier, it can be determined that the data unit is an encrypted data unit. If the header of the currently identified data unit does not contain an encryption identifier, it can be determined that the data unit is not an encrypted data unit.

[0106] In step 24, in response to determining an encrypted data unit among multiple data units, perform decryption processing on the encrypted data unit to obtain the target data unit corresponding to the encrypted data unit.

[0107] If an encrypted data unit can be determined among multiple data units, it is also necessary to further decrypt the encrypted data unit to obtain the data content corresponding to the encrypted data unit. Optionally, the encrypted data unit can be decrypted according to the encryption method adopted when the encrypted data unit is encrypted at the sending end of the video data. The receiving end with read permission should store the relevant information for decryption. Using this information, decryption can be achieved, and then the target data unit corresponding to the encrypted data unit, that is, the actual data content of the encrypted data unit, can be obtained. The decryption method is the same as the existing decryption method and will not be elaborated here.

[0108] In step 25, according to the target data unit, obtain the video data corresponding to the target video file through decoding processing.

[0109] In a possible implementation manner, if all the multiple data units obtained after reading the target video file are encrypted data units, the target data unit obtained in step 24 can be directly decoded to obtain the video data corresponding to the target video file.

[0110] In another possible implementation manner, if among the multiple data units obtained after reading the target video file, in addition to the encrypted data unit, there is also a second data unit other than the encrypted data unit, step 25 may include the following steps:

[0111] Decode the second data unit and the target data unit to obtain the video data corresponding to the target video file.

[0112] In the overall process of the present disclosure solution, after receiving a video file, in the decompression stage, it is possible to identify whether there is an encryption identification unit to determine whether the video file is an encrypted file. If there is an encryption identification unit, it is necessary to first perform data verification according to the key verification data carried by the encryption identification unit. After successful verification, the video file is decompressed into multiple data units. Among these data units, there are encrypted data units that have been encrypted. For such encrypted data units, they also need to be input into the decryption processing module for decryption to obtain the original decrypted data units. Furthermore, the decrypted data units and the data units that do not need to be decrypted are decoded to obtain the video data corresponding to the target video file.

[0113] Through the above technical solution, an encrypted video file can be quickly identified, and a preliminary verification of the video file can be performed based on a predefined method. After successful verification, further decryption of the encrypted data units is carried out until all the unencrypted original data units are obtained, and then the original video data is decoded and restored. Thus, the identification of whether a video file is encrypted can be quickly achieved, and at the same time, multiple levels of verification and decryption are set up, taking into account both security and processing efficiency.

[0114] Figure 3 It is a block diagram of a data processing device provided according to an embodiment of the present disclosure. As Figure 3 shown, the device 30 includes:

[0115] A first determination module 31, configured to determine a target data unit to be encrypted among multiple data units obtained after encoding processing for video data;

[0116] A first encryption module 32, configured to perform encryption processing on the target data unit to obtain an encrypted data unit;

[0117] A generation module 33, configured to generate a target video file corresponding to the video data at least according to the encrypted data unit, where the target video file includes an encryption identification unit for indicating that the file has been encrypted, and the encryption identification unit includes at least key verification data.

[0118] Optionally, the target data unit includes a header and a data part. The header of the target data unit is used to store the meta-information of the target data unit, and the data part of the target data unit is used to store the video content of the video frame corresponding to the target data unit;

[0119] The first encryption module 32 includes:

[0120] A first processing sub-module, configured to obtain the data part of the encrypted data unit by performing encryption processing on the data part of the target data unit;

[0121] A second processing sub-module, configured to obtain the header of the encrypted data unit by writing an encryption identifier to a target reserved bit in the header of the target data unit.

[0122] Optionally, the target data unit is all or part of the multiple data units.

[0123] Optionally, if the target data unit is part of the multiple data units, the generating module 33 includes:

[0124] A first determining sub-module, configured to determine a first data unit among the multiple data units other than the target data unit;

[0125] A generating sub-module, configured to generate the target video file by writing the first data unit and the encrypted data unit into a file.

[0126] Optionally, the encryption identifier unit includes a data header and a data body. The data header is used to store meta-information of the encryption identifier unit, and the data body is used to store the key verification data;

[0127] The key verification data is generated by the following modules:

[0128] A second determining module, configured to determine a first key;

[0129] A second encryption module, configured to encrypt specified key information using the first key to obtain the key verification data.

[0130] Optionally, the encryption identifier unit is located at the tail of the target video file.

[0131] Optionally, the target data unit is a data unit corresponding to an IDR frame of the video data.

[0132] Figure 4 is a block diagram of a data processing apparatus provided according to another embodiment of the present disclosure. As Figure 4 shown, the apparatus 40 includes:

[0133] An obtaining module 41, configured to obtain a target video file;

[0134] A verifying module 42, configured to perform data verification using the encryption identifier unit in response to detecting an encryption identifier unit for indicating that the file has been encrypted in the target video file;

[0135] A reading module 43, configured to read multiple data units included in the target video file when the data verification is successful;

[0136] A decryption module 44, configured to, in response to determining an encrypted data unit among the multiple data units, perform decryption processing on the encrypted data unit to obtain a target data unit corresponding to the encrypted data unit;

[0137] A decoding module 45, configured to obtain video data corresponding to the target video file through decoding processing according to the target data unit.

[0138] Optionally, the encryption identification unit at least includes key verification data;

[0139] The verification module 42 includes:

[0140] A second determination sub-module, configured to determine a second key;

[0141] An encryption sub-module, configured to encrypt specified key information by using the second key to obtain an encrypted string;

[0142] A matching sub-module, configured to determine that data verification is successful if the encrypted string matches the key verification data.

[0143] Optionally, the data unit includes a header;

[0144] The encrypted data unit is determined through the following module:

[0145] A third determination module, configured to, for each of the data units, determine whether an encryption identification exists in the header of the data unit;

[0146] A fourth determination module, configured to determine a data unit with an encryption identification as the encrypted data unit.

[0147] Optionally, among the multiple read data units, there is also a second data unit other than the encrypted data unit;

[0148] The decoding module 45 is configured to perform decoding processing on the second data unit and the target data unit to obtain video data corresponding to the target video file.

[0149] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.

[0150] Next, refer to Figure 5, which shows a schematic structural diagram of an electronic device 600 suitable for implementing the embodiments of the present disclosure. The terminal devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The shown electronic device is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0151] As Figure 5 shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to the programs stored in the read-only memory (ROM) 602 or the programs loaded from the storage device 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.

[0152] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 5 the shown electronic device 600 has various devices, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices may be implemented or had alternatively.

[0153] Particularly, according to the embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from the network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the methods of the embodiments of the present disclosure are executed.

[0154] It should be noted that the above-mentioned computer-readable medium in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0155] In some embodiments, the client can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0156] The above-mentioned computer-readable medium can be included in the above-mentioned electronic device; it can also exist separately without being assembled into the electronic device.

[0157] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: determine a target data unit to be encrypted among a plurality of data units obtained after encoding video data; perform an encryption process on the target data unit to obtain an encrypted data unit; generate a target video file corresponding to the video data at least based on the encrypted data unit, where the target video file includes an encryption identification unit for indicating that the file has been encrypted, and the encryption identification unit includes at least key verification data.

[0158] Alternatively, the above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: obtain a target video file; in response to detecting an encryption identification unit for indicating that the file has been encrypted in the target video file, perform data verification using the encryption identification unit; in the case where the data verification is successful, read a plurality of data units included in the target video file; in response to determining an encrypted data unit among the plurality of data units, perform a decryption process on the encrypted data unit to obtain a target data unit corresponding to the encrypted data unit; and obtain video data corresponding to the target video file through a decoding process based on the target data unit.

[0159] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0160] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur in a different order than that noted in the drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.

[0161] The modules described in the embodiments of the present disclosure can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the module itself in some cases. For example, the first determination module can also be described as "the module that determines the target data unit to be encrypted among multiple data units obtained after encoding video data".

[0162] The functions described above herein can be performed, at least in part, by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGA), Application Specific Integrated Circuits (ASIC), Application Specific Standard Products (ASSP), System on a Chip (SOC), Complex Programmable Logic Devices (CPLD), and so on.

[0163] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a Random Access Memory (RAM), a Read-Only Memory (ROM), an Erasable Programmable Read-Only Memory (EPROM or Flash Memory), an optical fiber, a portable Compact Disc Read-Only Memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0164] According to one or more embodiments of the present disclosure, a data processing method is provided, the method comprising:

[0165] Among a plurality of data units obtained after encoding video data, determining a target data unit to be encrypted;

[0166] Performing an encryption process on the target data unit to obtain an encrypted data unit;

[0167] Generating a target video file corresponding to the video data at least based on the encrypted data unit, the target video file including an encryption identification unit for indicating that the file has been encrypted, and the encryption identification unit at least includes key verification data.

[0168] According to one or more embodiments of the present disclosure, a data processing method is provided, the target data unit includes a header and a data part, the header of the target data unit is used to store meta-information of the target data unit, and the data part of the target data unit is used to store video content of a video frame corresponding to the target data unit;

[0169] The performing an encryption process on the target data unit to obtain an encrypted data unit includes:

[0170] Performing an encryption process on the data part of the target data unit to obtain the data part of the encrypted data unit;

[0171] Writing an encryption identification in a target reserved bit of the header of the target data unit to obtain the header of the encrypted data unit.

[0172] According to one or more embodiments of the present disclosure, a data processing method is provided, the target data unit is all or part of the plurality of data units.

[0173] According to one or more embodiments of the present disclosure, a data processing method is provided, if the target data unit is part of the plurality of data units, the generating a target video file corresponding to the video data at least based on the encrypted data unit includes:

[0174] Determining a first data unit among the plurality of data units other than the target data unit;

[0175] Generating the target video file by writing the first data unit and the encrypted data unit into a file.

[0176] According to one or more embodiments of the present disclosure, a data processing method is provided, the encryption identification unit includes a data header and a data body, the data header is used to store meta-information of the encryption identification unit, and the data body is used to store the key verification data;

[0177] The key verification data is generated in the following manner:

[0178] Determine a first key;

[0179] Use the first key to encrypt specified key information to obtain the key verification data.

[0180] According to one or more embodiments of the present disclosure, a data processing method is provided, and the encryption identification unit is located at the tail of the target video file.

[0181] According to one or more embodiments of the present disclosure, a data processing method is provided, and the target data unit is a data unit corresponding to the IDR frame of the video data.

[0182] According to one or more embodiments of the present disclosure, a data processing method is provided, and the method includes:

[0183] Obtain a target video file;

[0184] In response to detecting an encryption identification unit for characterizing that the file has been encrypted in the target video file, perform data verification using the encryption identification unit;

[0185] In the case where the data verification is successful, read a plurality of data units included in the target video file;

[0186] In response to determining an encrypted data unit among the plurality of data units, perform decryption processing on the encrypted data unit to obtain a target data unit corresponding to the encrypted data unit;

[0187] According to the target data unit, obtain video data corresponding to the target video file through decoding processing.

[0188] According to one or more embodiments of the present disclosure, a data processing method is provided, and the encryption identification unit at least includes key verification data;

[0189] The performing data verification using the encryption identification unit includes:

[0190] Determine a second key;

[0191] Use the second key to encrypt specified key information to obtain an encrypted string;

[0192] If the encrypted string matches the key verification data, determine that the data verification is successful.

[0193] According to one or more embodiments of the present disclosure, a data processing method is provided, and the data unit includes a header;

[0194] The encrypted data units are determined by the following method:

[0195] For each of the data units, determine whether an encryption identifier exists in the header of the data unit;

[0196] Determine the data units with encryption identifiers as the encrypted data units.

[0197] According to one or more embodiments of the present disclosure, a data processing method is provided. Among the read multiple data units, there are also second data units other than the encrypted data units;

[0198] Based on the target data unit, obtaining video data corresponding to the target video file through decoding processing includes:

[0199] Perform decoding processing on the second data unit and the target data unit to obtain video data corresponding to the target video file.

[0200] According to one or more embodiments of the present disclosure, a data processing device is provided. The device includes:

[0201] A first determination module, configured to determine a target data unit to be encrypted among multiple data units obtained after encoding processing for video data;

[0202] A first encryption module, configured to perform encryption processing on the target data unit to obtain encrypted data units;

[0203] A generation module, configured to generate a target video file corresponding to the video data at least based on the encrypted data units. The target video file includes an encryption identifier unit for indicating that the file has been encrypted, and the encryption identifier unit includes at least key verification data.

[0204] According to one or more embodiments of the present disclosure, a data processing device is provided. The device includes:

[0205] An acquisition module, configured to acquire a target video file;

[0206] A verification module, configured to perform data verification using the encryption identifier unit in response to detecting that an encryption identifier unit for indicating that the file has been encrypted exists in the target video file;

[0207] A reading module, configured to read multiple data units included in the target video file when the data verification is successful;

[0208] A decryption module, configured to decrypt an encrypted data unit in response to determining the encrypted data unit among the multiple data units, so as to obtain a target data unit corresponding to the encrypted data unit;

[0209] A decoding module, configured to obtain video data corresponding to the target video file through decoding processing according to the target data unit.

[0210] According to one or more embodiments of the present disclosure, there is provided a computer-readable medium, on which a computer program is stored, and when the program is executed by a processing device, the steps of the data processing method provided in any embodiment of the present disclosure are implemented.

[0211] According to one or more embodiments of the present disclosure, there is provided an electronic device, including:

[0212] A storage device, on which a computer program is stored;

[0213] A processing device, configured to execute the computer program in the storage device to implement the steps of the data processing method provided in any embodiment of the present disclosure.

[0214] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principle. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solution formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, a technical solution formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in the present disclosure.

[0215] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented combinatorially in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0216] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms for implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated herein.

Claims

1. A data processing method, characterized in that, The method includes: Among multiple data units obtained after encoding video data, determining a target data unit to be encrypted; Performing an encryption process on the target data unit to obtain an encrypted data unit; Generating a target video file corresponding to the video data at least based on the encrypted data unit, where the target video file includes an encryption identification unit for indicating that the file has been encrypted, and the encryption identification unit at least includes key verification data.

2. The method according to claim 1, characterized in that, The target data unit includes a header and a data part. The header of the target data unit is used to store meta-information of the target data unit, and the data part of the target data unit is used to store video content of a video frame corresponding to the target data unit; The performing an encryption process on the target data unit to obtain an encrypted data unit includes: Performing an encryption process on the data part of the target data unit to obtain the data part of the encrypted data unit; Writing an encryption identification into a target reserved bit in the header of the target data unit to obtain the header of the encrypted data unit.

3. The method according to claim 1, wherein The target data unit is all or part of the multiple data units.

4. The method according to claim 3, characterized in that, If the target data unit is part of the multiple data units, the generating a target video file corresponding to the video data at least based on the encrypted data unit includes: Determining a first data unit among the multiple data units other than the target data unit; Generating the target video file by writing the first data unit and the encrypted data unit into a file.

5. The method according to claim 1, wherein The encryption identification unit includes a data header and a data body. The data header is used to store meta-information of the encryption identification unit, and the data body is used to store the key verification data; The key verification data is generated by the following method: Determining a first key; Encrypting specified key information using the first key to obtain the key verification data.

6. The method according to claim 1, characterized in that, The encryption identification unit is located at the tail of the target video file.

7. The method according to any one of claims 1-6, characterized in that The target data unit is a data unit corresponding to an IDR frame of the video data.

8. A data processing method, characterized in that, The method includes: Obtaining a target video file; In response to detecting an encryption identification unit for indicating that the file has been encrypted in the target video file, performing data verification using the encryption identification unit; In the case where the data verification is successful, reading multiple data units included in the target video file; In response to determining an encrypted data unit among the multiple data units, performing a decryption process on the encrypted data unit to obtain the target data unit corresponding to the encrypted data unit; Based on the target data unit, obtaining video data corresponding to the target video file through a decoding process.

9. The method according to claim 8, characterized in that, The encryption identification unit at least includes key verification data; The performing data verification using the encryption identification unit includes: Determining a second key; Encrypting specified key information using the second key to obtain an encrypted string; If the encrypted string matches the key verification data, determining that the data verification is successful.

10. The method according to claim 8, wherein The data unit includes a header; Determining the encrypted data unit by the following method: For each of the said data units, determine whether an encryption identifier exists in the header of the data unit; Determine the data unit with an encryption identifier as the said encrypted data unit.

11. The method according to claim 8, wherein Among the multiple read data units, there are also second data units other than the said encrypted data units; The obtaining the video data corresponding to the target video file through decoding processing according to the target data unit includes: Performing decoding processing on the second data unit and the target data unit to obtain the video data corresponding to the target video file.

12. A data processing device, characterized in that, The device includes: A first determination module, configured to determine a target data unit to be encrypted among multiple data units obtained after encoding processing on video data; A first encryption module, configured to perform encryption processing on the target data unit to obtain an encrypted data unit; A generation module, configured to generate a target video file corresponding to the video data at least according to the encrypted data unit, where the target video file includes an encryption identifier unit for indicating that the file has been encrypted, and the encryption identifier unit includes at least key verification data.

13. A data processing device, characterized in that, The device includes: An acquisition module, configured to acquire a target video file; A verification module, configured to perform data verification using the encryption identifier unit in response to detecting that an encryption identifier unit for indicating that the file has been encrypted exists in the target video file; A reading module, configured to read multiple data units included in the target video file when the data verification is successful; A decryption module, configured to perform decryption processing on the encrypted data unit in response to determining an encrypted data unit among the multiple data units to obtain the target data unit corresponding to the encrypted data unit; A decoding module, configured to obtain the video data corresponding to the target video file through decoding processing according to the target data unit.

14. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by a processing device, it implements the steps of the method according to any one of claims 1-11.

15. An electronic device, characterized in that, Including: A storage device, on which a computer program is stored; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1-11.